Back after a week off — a heavy flu 🤒 kept me away from the keyboard. Apologies for the gap.
This week the Australian government criticized OpenAI for waiting months to report that one of its agents had bypassed controls on a Medicare statistics portal and accessed non-public files. Google confirmed that a Gemini model accidentally accessed three real companies during a May security test, stopped each time, and that no harm was done. OpenAI's Codex had two separate sandbox escapes patched this week, the worst of which leaked a trust token from shared memory to reach native processes. Anthropic reported its fourth escape last issue. The phrase "no harm was done" is now doing a lot of work across a lot of press releases.
At some point the individual incident stops being the story. The pattern is. AI models escaping sandboxes during testing, accessing production systems at third parties, and being reported months later — or not at all — is no longer a series of anomalies. It's a category. The industry's current response posture is roughly: detect, contain, patch, reassure. That posture was designed for software vulnerabilities with a CVE and a patch cycle. It is not obviously the right framework for systems that make autonomous decisions about what the sandbox is for.
Table of Contents
🔓 BREACHES & SECURITY INCIDENTS
🇺🇸 Hacking group ShinyHunters says it breached FBI systems and stole personal data on thousands of agents and job applicants. The group claims they accessed Oracle PeopleSoft and an Amazon-hosted government cloud and took terabytes of information. The stolen data could be used to extort or coerce agents and their families, creating a major counterintelligence risk.
💸 Hackers suspected to be from North Korea stole about $351.6 million from Bitget’s hot and warm wallets. Bitget has paused withdrawals while it investigates, but trading and deposits continue. The company says customer funds are covered by its protection fund and most assets remain safe.
🇺🇸 Hackers stole customer data from some BigCommerce stores by misusing a key from the third-party Ribon app. The stolen data included names, email addresses, phone numbers, and addresses. BigCommerce disabled the key, removed the app from affected stores, and notified merchants.
🇸🇪 Sweden’s data regulator fined IT firm Miljödata $183,000 after a cyberattack in August 2025 exposed data on 2.2 million people. The company failed to properly check new software and lacked real-time monitoring, violating GDPR security rules. The stolen data, including IDs and health and school records, was later posted on the dark web.
💰 Ambry Genetics agreed to pay a $700,000 HIPAA fine and improve security after a 2020 phishing attack exposed data of 225,370 patients. The company already settled a civil class action for $12.25 million over the same breach. Ambry's parent, Tempus AI, now faces separate lawsuits alleging improper use and transfer of patients' genetic data.
🇫🇷 French firm CrowdSec confirmed that attackers stole source code from about 300 of its GitHub repositories in a May 2026 supply-chain breach. Around 170 of the affected repos were private, but CrowdSec says no customer credentials or data were leaked. The company says the stolen code alone cannot be used to harm customers and it has rotated all possibly affected tokens.
🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s
🇺🇸 ⚖ Karen Vardanyan was sentenced to two years in prison for helping carry out Ryuk ransomware attacks. He must also pay about $1.2 million in restitution. The attacks targeted businesses, schools, and other organizations.
🇵🇰 🐀 🇮🇳 SideCopy, a Pakistan-linked hacking group, is now targeting Indian academic institutions with phishing emails. The attacks use disguised files and hidden scripts to install ReverseRAT malware. ReverseRAT can steal data, run commands, and maintain access to infected computers.
💳 A criminal used AI tools to attack hundreds of retailers and steal more than 600,000 credit card records. The campaign placed skimmers on at least 119 websites and sometimes erased stolen data from retailers’ databases. Low costs and automation make these attacks easier to carry out at scale.
🇨🇳 Volexity says a China-aligned group exploited three Chrome and Windows flaws before they were patched. The group used fake websites and phishing emails to target Asian organizations. Researchers say several Chinese groups may be sharing and adapting the same attack tools.
🇰🇵 🗾 Japan, the US and allies say a North Korean group called WaterPlum used fake job offers to infect devices and steal crypto. They linked the group to North Korea’s IT operations and dismantled Japan’s first-known laptop farm. The scheme stole millions, exposed company networks, and used fake interviews and AI tricks to hide operatives.
❌ 📨 Microsoft and partners seized websites and disabled domains to take down EvilTokens, an AI-driven phishing-as-a-service that compromised over 12,000 Microsoft customer inboxes. The platform let criminals use AI to analyze victims, bypass protections, and run business-email compromise and financial fraud schemes. Authorities arrested two suspected operators in the U.K., but experts warn the criminal model could reappear.
🗓️ {Cyber,Info}Sec Events — A community-maintained list of infosec conferences worldwide. Subscribe to the ICS calendar feed to get events straight into your calendar, or follow @[email protected] on Mastodon for weekly digests. Contributions and ⭐ welcome!
👨🏻⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY
🇺🇸 🇷🇺 U.S. prosecutors say Oxygen Forensics hid its Russian ownership to win government contracts. CEO Lee Reiber and Russian executive Oleg Davydov were arrested and charged with conspiracy to commit wire fraud. The Justice Department says there is no claim the software contained malicious code or accessed customer data without permission.
🇮🇪 Ireland’s Data Protection Commission fined Google €403 million for GDPR breaches over how it used and stored users’ location data. The DPC found Google lacked transparency and kept location data too long across several features. Google says it has updated policies and added easier controls for managing and deleting location data.
🦠 MALWARE & THREATS
🇰🇵 Attackers hid Go malware in Terraform providers and software packages, using fake job offers to target developers. The malware can steal system details and receive commands through Slack and blockchain networks. Researchers warn that these North Korea-linked campaigns are spreading to more developer tools and accounts.
🏦 RemControl is Android malware targeting banking users in Europe, Canada, and the Middle East through a fake TVTap app. It can steal login details and control infected phones. Users should avoid untrusted app downloads and deny unnecessary Accessibility permissions.
🍎 Malware on a Mac can change a hidden Muse setting so the assistant sends dictated audio and text to an attacker instead of Meta. The exploit only works if the attacker can already run code as the logged-in user, but then lets them read dictation, add trusted instructions, and hijack the Muse session. Until Meta fixes it, quit or remove Muse, revoke unneeded permissions, and avoid using voice input.
🐀 RatHat is an Android trojan that uses generative AI to read the screen and automatically navigate and control infected devices. It steals credentials, captures PINs and touch events, hides itself, and can reinstall if removed. The malware uses a Go agent and reverse-proxy tunnel to give attackers persistent, system-level access.
📦 A malicious npm package pretended to be a Twilio bug-bounty tool — Some versions stole system data and Twilio credentials, while others probed Twilio-related systems. Researchers say it violated Twilio’s security rules and likely had malicious intent.
📦 A malicious npm package named indexed-btree hid its loader inside a runtime method to bypass install-time defenses. It impersonated a real library, reached millions of downloads, and can exfiltrate system data and fetch encrypted payloads via an Ethereum contract. Developers should use runtime behavioral analysis, rotate secrets, and restore from clean backups if they used the package.
🤖 🧰 AI, CRYPTO, TECH & TOOLS
🤡 President Trump told the United Nations the U.S. will call all AI "super intelligence" instead of "artificial intelligence." He said "artificial" sounds fake and prefers "super", though experts use "superintelligence" to mean AI that surpasses humans. Industry figures and labs have mixed or amused reactions and it’s unclear if the term will stick.
🇦🇺 An OpenAI AI agent bypassed controls on an Australian Medicare statistics portal and accessed non-public files, but investigators found no evidence that patient records were exposed. The government criticized OpenAI for waiting months to report the incident and is investigating what happened. The case has prompted a review of how Australia handles cybersecurity incidents involving AI.
🇪🇸 Spanish PM Pedro Sánchez said AI cannot be left to self-regulation by tech firms. He unveiled a 12-month plan for responsible AI, including an AI gigafactory and models for climate, health and energy. He called for strict environmental, energy and data standards and stronger cybersecurity.
🧩 Researcher Gal Weizman revealed BragJack, a method where a single malicious browser extension can hijack built-in AI agents in Chromium-based browsers. The attacks let the extension silently control agents to read files, take screenshots, access history, and perform actions on websites. Vendors fixed the flaws and paid bounties, but users should update browsers and remove untrusted extensions.
🐛 Researchers found two sandbox escapes in OpenAI Codex that let untrusted agent code run commands on a developer's machine. The worst, called Heapjack, leaks a trust token from shared memory so the agent can send requests to native processes. OpenAI patched both flaws quickly; users should update Codex Desktop and CLI to the fixed versions.
🙊 Google confirmed a Gemini model accidentally accessed three real companies during a May security test. The model stopped each time and Google says no harm was done. Other AI firms have reported similar testing escapes and are tightening protections.
🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE
➝ From the Patching Department:
📄 CISA outlined four areas to improve the CVE vulnerability program: governance, participation, data systems, and record quality. The program faces a surge in reported vulnerabilities and a growing backlog of records needing more detail. Experts welcomed CISA’s plan but said it needs clearer steps, consistent scoring, and enough resources.
🐧 A Linux kernel flaw can let an attacker escape an Ubuntu container and gain root access to the host. Exploit code is available, but Ubuntu has not yet released a fix for affected versions. Until then, experts recommend isolating untrusted workloads in microVMs.
🐧 A Linux flaw can let certain ARM64 virtual machines read and change host memory, potentially escaping to the host. It affects hosts with nested virtualization enabled, which is off by default, and cannot be exploited over a network. Updates fix the flaw; affected systems should be patched.
⚠ 🇨🇳 Chinese hackers exploited a critical ZyXEL GS1900 switch flaw (CVE-2026-7273) to steal sensitive data from nearly 1,000 devices worldwide. They used an obfuscated Python script to exfiltrate hashed credentials, configs, and network details, with many devices still using factory passwords. CISA added the bug to its KEV list and urged immediate patching as the attacker also targeted Ubiquiti, WordPress, and government systems.
🛰️ ICS, OT & IoT
💬 NIST is seeking comments on an updated guide for securing operational technology, with comments due November 30, 2026. CISA and the FBI warn that third-party industrial control system integrators can create security risks. They urge operators to limit access, set clear security rules in contracts, and monitor remote connections.
⚠ D-Link warned that older DIR-822A routers have a critical flaw that attackers can exploit, and public attack code is available. No patches are ready, and D-Link is investigating a second flaw. The company advises owners to keep routers off the internet and restrict remote and admin access.
🇺🇦 OpenAI and Ukraine are partnering to use AI to defend critical infrastructure from cyberattacks. The tools will help Ukrainian experts spot and respond to threats faster, not replace them. The effort aims to keep vital services like power and water running.
🇺🇸 💧 Hackers attacked operational technology at two small Colorado water utilities and changed equipment settings, but water service and public safety were not affected. The governor’s office said “foreign actors” were involved and noted possible links to Iran-backed campaigns, though this is unconfirmed. Federal agencies warn of wider attacks on water systems and urge better OT security.
💬 CONNECT
Follow me on Mastodon for quick daily updates and bite-sized content.
Prefer using an RSS feed? Add Infosec MASHUP to your feed here.
Enjoying our newsletter? Forward it to a colleague—
it’s one of the best ways to support us.
Thanks for reading today’s newsletter, and if you're enjoying it and want to support my work, you can buy me a coffee ☕ over at https://www.buymeacoffee.com/0x58
See you next time!
-X.


